Technology
Box Hill Tech Companies Adopt Continuous AI Cybersecurity Training Over Annual Modules
The city's companies are moving ahead of other global tech centres by replacing annual modules with ongoing deepfake simulations and human risk programs.
How we reported this
Box Hill technology firms began rolling out continuous AI-powered human risk management programs in 2026, replacing the old annual compliance modules with live deepfake and threat simulations.
The change arrives as human error continues to drive most breaches. Sentinel One data shows 68 percent of data breaches involve a human element while 88 percent trace directly to human mistakes. Global surveys reinforce the timing, with 94 percent of respondents naming AI the leading driver of cybersecurity change and 87 percent flagging AI-related vulnerabilities as the fastest-growing risk.
Why Box Hill firms adopted the new model first
Box Hill companies operate inside a dense cluster of software developers, fintech start-ups and cloud providers that share threat intelligence daily. This density lets them test simulation platforms across multiple offices at once and adjust training in real time when new deepfake tactics appear. The approach differs from the slower, calendar-based refresh cycles still common in other major tech cities where training remains a once-a-year checkbox.
Local teams now run weekly micro-simulations that mimic business email compromise and ransomware delivery. Participants receive immediate feedback on their decisions, and the platform logs repeat errors so managers can target follow-up coaching. The national cyber awareness campaign supports the effort by publishing incident data that shows one cybercrime reported every six minutes on average, giving Box Hill firms fresh material for their scenario libraries.
Next steps for companies still using annual training
Organisations that want to match the pace should begin by auditing their current modules for simulation content rather than lecture format. They can then pilot short deepfake exercises with one department before expanding. Adaptive Security notes that platforms already exist to automate scenario creation and track behaviour change without adding headcount. Firms that complete the switch report fewer repeat incidents because staff practice responses under conditions that mirror actual attacks rather than reading static policy documents.